CVE-2024-0964

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in pypi/gradio

Identifiers

GHSA-f3h9-8phc-6gvh, CVE-2024-0964

Package Slug

pypi/gradio

Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Description

A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

Affected Versions

All versions before 4.9.0

Solution

Upgrade to version 4.9.0 or above.

Last Modified

2024-02-07

source